-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-drupal7-14.1-jessie-amd64.ova.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-drupal7-14.1-jessie-amd64.ova 5301b3955aaace7eaf593d315411ca01 $ sha1sum turnkey-drupal7-14.1-jessie-amd64.ova b8c168c78b0343cf913a01638f1a11312a93129b -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnyAAoJEIXCXpWhbrlNX3UIAKWWebpsqZhbQZceD53n8fcS qtAcMnQy2/nT4zJSzhTRmPIVsIK7uLNooBhrm8rXzG9ifQNUVC5p1hfthnqa3l+O SDOkf5ho3P7fJ/PSbAtporKAmFopFnzgyKX9J2Ekv48Dva6Pt+CO0rbRivk58ZGC S0jUA7nS6mHZnNdgguBsnAgtIfgufCqfKQnrExd7jKO9i0yNvf9YVsiwKxHrgy7N a3pt4bwag3OGSBsjXn6Smz91k8Y52d/cbqedUfsnzehFCVXVdMCosFmGLqJoSzLy 1RUkTpQJWYC5cWMmVy58xxHd5cLcSc6BrhDqDPkhQmmogbTSI1Y+5rvxV54SBOQ= =PxWN -----END PGP SIGNATURE-----